[BreachExchange] Solara Medical Supplies Provides Notice of a Data Breach

Destry Winant destry at riskbasedsecurity.com
Thu Nov 14 10:09:17 EST 2019


https://www.prnewswire.com/news-releases/solara-medical-supplies-provides-notice-of-a-data-breach-300957962.html

CHULA VISTA, Calif., Nov. 13, 2019 /PRNewswire/ -- Solara Medical Supplies,
LLC ("Solara") provides notice of an incident that may affect the security
of some information relating to certain individuals associated with Solara
including current and former patients and employees.

*What Happened? *On June 28, 2019, Solara determined that an unknown actor
gained access to a limited number of employee Office 365 accounts, from April
2, 2019 to June 20, 2019, as a result of a phishing email campaign. Solara
worked with third party forensic experts to investigate and respond to this
incident and confirm the security of relevant Solara systems. Through this
investigation on July 3, 2019, Solara determined that certain information
present within the employee Office 365 accounts may have been accessed or
acquired by an unknown actor at the time of the incident. Solara undertook
a comprehensive manual and programmatic review of the accounts to identify
what personal information was stored within the accounts and to whom that
information related.

*What Information Was Involved?  *The personal information present in the
accounts at the time of the incident varied by individual but may have
included first and last names and one or more of the following data
elements: name, address, date of birth, Social Security number, Employee
Identification Number, medical information, health insurance information,
financial information, credit / debit card information, driver's license /
state ID, passport information, password / PIN or account login
information, billing / claims information, and Medicare ID / Medicaid ID.

*What is Solara Doing?  *Solara takes this incident and security of
personal information in its care seriously. Solara moved quickly to
investigate and respond to this incident, assess the security of relevant
Solara systems, and notify potentially affected individuals. This response
included resetting relevant account passwords and reviewing and enhancing
existing Solara policies and procedures to reduce the likelihood of a
similar future event.  Solara reported this incident to law enforcement and
relevant state and federal regulators.  Solara is also notifying
potentially impacted individuals so that they may take further steps to
best protect their information, should they feel it is appropriate to do
so.  In an abundance of caution, Solara is offering access to credit
monitoring and identity protection services at no cost to impacted
individuals.

*What Can Impacted Individuals Do?  *Solara has established a dedicated
assistance line for individuals seeking additional information regarding
this incident. Individuals may call 1-877-460-0157 (toll free), Monday
through Friday from 8:00 a.m. to 5:30 p.m. Central Time with questions if
they would like additional information.  Individuals may also write to
Solara at 2084 Otay lakes Rd #102, Chula Vista, CA 91913 or email
Compliance at solaramedicalsupplies.com with questions.  Additional
information can also be found on Solara's website,
https://www.solara.com/dataincident
<https://c212.net/c/link/?t=0&l=en&o=2642460-1&h=3363023005&u=https%3A%2F%2Fwww.solara.com%2Fdataincident&a=https%3A%2F%2Fwww.solara.com%2Fdataincident>.
Potentially affected individuals may also consider the information and
resources outlined below.

Solara encourages potentially impacted individuals to remain vigilant
against incidents of identity theft and fraud and to review account
statements, credit reports, and explanation of benefits forms for
suspicious activity.  Under U.S. law, individuals with credit reports are
entitled to one free credit report annually from each of the three major
credit reporting bureaus. To order your free credit report, visit
www.annualcreditreport.com
<https://c212.net/c/link/?t=0&l=en&o=2642460-1&h=1031354552&u=http%3A%2F%2Fwww.annualcreditreport.com%2F&a=www.annualcreditreport.com>
or
call, toll-free, 1-877-322-8228.  Individuals may also contact the three
major credit bureaus directly to request a free copy of their credit
report. The credit reporting agencies may be contacted as follows:
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.riskbasedsecurity.com/pipermail/breachexchange/attachments/20191114/7d9468bc/attachment.html>


More information about the BreachExchange mailing list